From 6476c5fd01cd588fd88653477398d01a058bbc82 Mon Sep 17 00:00:00 2001 From: Valera V Harseko Date: Fri, 2 Oct 2026 21:12:34 +0300 Subject: [PATCH 1/2] [#1161] Keep bc-fips from seeding its DRBG from RDSEED in the test JVMs On busy CI hosts the CPU's RDSEED instruction runs dry, and bc-fips 2.1.3 fails with "RDSEED persistently failed to produce entropy" while the embedded test server generates its self-signed certificates. The test class that starts the server then fails and the rest of it is skipped. Run the test JVMs with -Dorg.bouncycastle.native.cpu_variant=java, in both the default argLine and the jdk17.options one, so that bc-fips does not load its native libraries and seeds its DRBG from the JDK instead. The packaged server and the "Test on Unix FIPS" step are not affected. Fixes #1161 --- pom.xml | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/pom.xml b/pom.xml index 90321b5e1a..21d616414d 100644 --- a/pom.xml +++ b/pom.xml @@ -59,7 +59,13 @@ 2.9.1 5.5 1.0b3 - -Xmx512m + + -Xmx512m -Dorg.bouncycastle.native.cpu_variant=java tomcat10x https://doc.openidentityplatform.org/opendj/ @@ -735,7 +741,7 @@ [17,) - -Xmx512m --add-opens java.base/java.lang=ALL-UNNAMED --add-opens java.base/java.lang.reflect=ALL-UNNAMED --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/java.net=ALL-UNNAMED --add-opens java.base/java.io=ALL-UNNAMED --add-opens java.base/java.util.regex=ALL-UNNAMED --add-opens java.base/java.security=ALL-UNNAMED --add-opens java.naming/javax.naming.spi=ALL-UNNAMED + -Xmx512m -Dorg.bouncycastle.native.cpu_variant=java --add-opens java.base/java.lang=ALL-UNNAMED --add-opens java.base/java.lang.reflect=ALL-UNNAMED --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/java.net=ALL-UNNAMED --add-opens java.base/java.io=ALL-UNNAMED --add-opens java.base/java.util.regex=ALL-UNNAMED --add-opens java.base/java.security=ALL-UNNAMED --add-opens java.naming/javax.naming.spi=ALL-UNNAMED tomcat11x From 86074013876a084a0772ebcb6307965e91e71ea1 Mon Sep 17 00:00:00 2001 From: Valera V Harseko Date: Sun, 4 Oct 2026 11:44:11 +0300 Subject: [PATCH 2/2] [#1161] Hand the bc-fips flag to the JVMs the tests start from the package, and pin it The argLine flag stays inside the failsafe fork. AdsTrustStoreInstallTestCase and QuickSetupTestCase start the packaged setup, and ServerControllerTest starts start-ds through ServerController, which keeps the environment of the fork and drops only OPENDJ_JAVA_ARGS and CLASSPATH. Those servers generate their certificates through bc-fips with the native libraries loaded, which is the road of #1161. Set JAVA_TOOL_OPTIONS in the failsafe environment of opendj-server-legacy, so that every JVM started from the fork reads the flag as well. Pin both places: BcFipsNativeLibrariesOffTestCase in opendj-core fails when either root argLine loses the flag (LDAPServer generates its key pairs with bc-fips there, and the module takes the root argLine as it is), and BcFipsNativeLibrariesOffTest in opendj-server-legacy fails when the fork loses JAVA_TOOL_OPTIONS. --- .../BcFipsNativeLibrariesOffTestCase.java | 35 +++++++++++++ opendj-server-legacy/pom.xml | 9 ++++ .../util/BcFipsNativeLibrariesOffTest.java | 52 +++++++++++++++++++ pom.xml | 3 +- 4 files changed, 98 insertions(+), 1 deletion(-) create mode 100644 opendj-core/src/test/java/org/forgerock/opendj/ldap/BcFipsNativeLibrariesOffTestCase.java create mode 100644 opendj-server-legacy/src/test/java/org/opends/server/util/BcFipsNativeLibrariesOffTest.java diff --git a/opendj-core/src/test/java/org/forgerock/opendj/ldap/BcFipsNativeLibrariesOffTestCase.java b/opendj-core/src/test/java/org/forgerock/opendj/ldap/BcFipsNativeLibrariesOffTestCase.java new file mode 100644 index 0000000000..c88964c0c3 --- /dev/null +++ b/opendj-core/src/test/java/org/forgerock/opendj/ldap/BcFipsNativeLibrariesOffTestCase.java @@ -0,0 +1,35 @@ +/* + * The contents of this file are subject to the terms of the Common Development and + * Distribution License (the License). You may not use this file except in compliance with the + * License. + * + * You can obtain a copy of the License at legal/CDDLv1.0.txt. See the License for the + * specific language governing permission and limitations under the License. + * + * When distributing Covered Software, include this CDDL Header Notice in each file and include + * the License file at legal/CDDLv1.0.txt. If applicable, add the following below the CDDL + * Header, with the fields enclosed by brackets [] replaced by your own identifying + * information: "Portions copyright [year] [name of copyright owner]". + * + * Copyright 2026 3A Systems, LLC. + */ +package org.forgerock.opendj.ldap; + +import static org.testng.Assert.assertEquals; + +import org.testng.annotations.Test; + +/** + * Pins the test argLine flag that keeps bc-fips from seeding its DRBG from the CPU's RDSEED + * instruction, see issue #1161. {@link LDAPServer} generates its key pairs with bc-fips, and this + * module takes the argLine of the root pom as it is: the default one below JDK 17, the + * jdk17.options one from JDK 17 on. + */ +@SuppressWarnings("javadoc") +public class BcFipsNativeLibrariesOffTestCase extends SdkTestCase { + @Test + public void testJvmRunsWithoutTheNativeLibraries() { + assertEquals(System.getProperty("org.bouncycastle.native.cpu_variant"), "java", + "the test argLine lost the bc-fips cpu_variant flag, see #1161"); + } +} diff --git a/opendj-server-legacy/pom.xml b/opendj-server-legacy/pom.xml index 81ba8ee273..dbb91d28db 100644 --- a/opendj-server-legacy/pom.xml +++ b/opendj-server-legacy/pom.xml @@ -1282,6 +1282,15 @@ (org\.opends\.server\.replication\.service\..*)|(org\.opends\.server\.replication\.GenerationIdTest)|(org\.opends\.server\.types\.HostPortTest)|(org\.openidentityplatform\.opendj\.AliasTestCase) + + + -Dorg.bouncycastle.native.cpu_variant=java + @{argLine} false 1 diff --git a/opendj-server-legacy/src/test/java/org/opends/server/util/BcFipsNativeLibrariesOffTest.java b/opendj-server-legacy/src/test/java/org/opends/server/util/BcFipsNativeLibrariesOffTest.java new file mode 100644 index 0000000000..b9e4a8e1ae --- /dev/null +++ b/opendj-server-legacy/src/test/java/org/opends/server/util/BcFipsNativeLibrariesOffTest.java @@ -0,0 +1,52 @@ +/* + * The contents of this file are subject to the terms of the Common Development and + * Distribution License (the License). You may not use this file except in compliance with the + * License. + * + * You can obtain a copy of the License at legal/CDDLv1.0.txt. See the License for the + * specific language governing permission and limitations under the License. + * + * When distributing Covered Software, include this CDDL Header Notice in each file and include + * the License file at legal/CDDLv1.0.txt. If applicable, add the following below the CDDL + * Header, with the fields enclosed by brackets [] replaced by your own identifying + * information: "Portions copyright [year] [name of copyright owner]". + * + * Copyright 2026 3A Systems, LLC. + */ +package org.opends.server.util; + +import static org.testng.Assert.assertEquals; +import static org.testng.Assert.assertNotNull; +import static org.testng.Assert.assertTrue; + +import java.util.Arrays; + +import org.opends.server.DirectoryServerTestCase; +import org.testng.annotations.Test; + +/** + * Pins the flag that keeps bc-fips from seeding its DRBG from the CPU's RDSEED instruction in the + * test JVMs and in the JVMs they start from the built package, see issue #1161. + */ +@SuppressWarnings("javadoc") +public class BcFipsNativeLibrariesOffTest extends DirectoryServerTestCase +{ + private static final String FLAG = "-Dorg.bouncycastle.native.cpu_variant=java"; + + @Test + public void theTestJvmRunsWithoutTheNativeLibraries() + { + assertEquals(System.getProperty("org.bouncycastle.native.cpu_variant"), "java", + "the test JVM lost the bc-fips cpu_variant flag, see #1161"); + } + + /** setup, and start-ds through ServerController, inherit the environment of the failsafe fork. */ + @Test + public void theJvmsStartedFromThePackageInheritTheFlag() + { + final String toolOptions = System.getenv("JAVA_TOOL_OPTIONS"); + assertNotNull(toolOptions, "the failsafe fork lost JAVA_TOOL_OPTIONS, see #1161"); + assertTrue(Arrays.asList(toolOptions.trim().split("\\s+")).contains(FLAG), + "JAVA_TOOL_OPTIONS of the failsafe fork lost the bc-fips cpu_variant flag, see #1161: " + toolOptions); + } +} diff --git a/pom.xml b/pom.xml index 21d616414d..88f178f484 100644 --- a/pom.xml +++ b/pom.xml @@ -63,7 +63,8 @@ org.bouncycastle.native.cpu_variant=java keeps bc-fips from loading its native libraries in the test JVMs, so its DRBG is seeded from the JDK instead of the CPU's RDSEED instruction, which runs dry on busy CI hosts ("RDSEED persistently failed to produce entropy"), see issue #1161. - Keep it in the jdk17.options argLine below as well. + Keep it in the jdk17.options argLine below as well; BcFipsNativeLibrariesOffTestCase in + opendj-core fails when either argLine loses it. --> -Xmx512m -Dorg.bouncycastle.native.cpu_variant=java tomcat10x